Vulnerability index

Browse CVEs

114 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
I HIGH 8.8
CVE-2026-16908

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vul…

No fix yet
Fix from $4,900 2026-08-13
I Access Client Solutions HIGH 8.8
CVE-2026-13105

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration.

No fix yet
Fix from $4,900 2026-08-12
I MEDIUM 6.5
CVE-2026-17266

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to …

Fix: after 7.6
Fix from $4,000 2026-08-12
I HIGH 7.1
CVE-2026-17094

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal…

Fix unknown
Fix from $4,900 2026-08-12
App Connect Enterprise CRITICAL 9.8
CVE-2026-15435

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the sy…

Fix: 12.0.12.28 / 13.0.8.0+
Fix from $2,300 2026-07-30
App Connect Enterprise HIGH 7.5
CVE-2026-14519

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a …

Fix: 12.0.12.28 / 13.0.8.0+
Fix from $1,950 2026-07-30
Websphere Application Server HIGH 7.5
CVE-2026-15280

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability i…

Fix: 26.0.0.9+
Fix from $1,950 2026-07-28
Aspera CRITICAL 9.3
CVE-2026-14973

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

Fix: after 1.0.19
Fix from $2,300 2026-07-28
Websphere Application Server HIGH 7.5
CVE-2026-11595

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integra…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-06-30
Aspera High Speed Transfer Endpoint MEDIUM 6.5
CVE-2026-9035

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…

Fix: after 4.4.6
Fix from $1,600 2026-05-27
Infosphere Optim Test Data Fabrication HIGH 7.5
CVE-2026-3366

IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote …

Mitigation only
Fix from $1,950 2026-05-27
Webmethods Api Gateway MEDIUM 6.5
CVE-2026-2606

IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to …

Mitigation only
Fix from $1,600 2026-03-03
Websphere Application Server HIGH 7.6
CVE-2025-14914

IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal se…

Fix: after 26.0.0.1
Fix from $1,950 2026-02-02
Vios CRITICAL 9.1
CVE-2025-36236

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse …

Mitigation only
Fix from $2,300 2025-11-13
Tivoli Monitoring CRITICAL 9.8
CVE-2025-3356

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could …

Mitigation only
Fix from $2,300 2025-10-30
Tivoli Monitoring HIGH 7.5
CVE-2025-3355

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could …

Mitigation only
Fix from $1,950 2025-10-30
Soar Qradar Plugin App HIGH 7.5
CVE-2025-36114

IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An attacker could send a speciall…

Fix: after 5.6.0
Fix from $1,950 2025-08-20
Planning Analytics Local MEDIUM 6.5
CVE-2025-33004

IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction.

Mitigation only
Fix from $1,600 2025-06-01
Sterling Secure Proxy HIGH 7.5
CVE-2024-51453

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a speci…

Fix: after 6.2.0.1
Fix from $1,950 2025-05-28
Concert MEDIUM 5.3
CVE-2024-55913

IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially craf…

Fix: 1.1.0+
Fix from $1,600 2025-05-02
Cognos Analytics MEDIUM 6.5
CVE-2025-0823

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An atta…

Fix: 11.2.4 / 12.0.4+
Fix from $1,600 2025-02-28
Entirex MEDIUM 6.5
CVE-2024-54169

IBM EntireX 11.1 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request …

Mitigation only
Fix from $1,600 2025-02-27
Openpages With Watson MEDIUM 6.5
CVE-2024-49780

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges …

Fix: 8.3.0.3 / 9.0.0.5+
Fix from $1,600 2025-02-20
Power Hardware Management Console MEDIUM 6.5
CVE-2024-56477

IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a …

Mitigation only
Fix from $1,600 2025-02-14
App Connect Enterprise MEDIUM 6.5
CVE-2025-0799

IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file …

Fix: after 13.0.2.1
Fix from $1,600 2025-02-06
Cloud Pak System MEDIUM 5.3
CVE-2023-38012

IBM Cloud Pak System 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could allow a remote attacker to traverse directories…

Mitigation only
Fix from $1,600 2025-01-25
Maximo Asset Management HIGH 7.5
CVE-2024-45652

IBM Maximo MXAPIASSET API 7.6.1.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL…

Mitigation only
Fix from $1,950 2025-01-19
Infosphere Information Server HIGH 7.5
CVE-2024-52363

IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafte…

Mitigation only
Fix from $1,950 2025-01-17
Engineering Lifecycle Optimization Publishing MEDIUM 6.5
CVE-2024-41765

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker …

Mitigation only
Fix from $1,600 2025-01-04
Sterling Secure Proxy HIGH 7.5
CVE-2024-41784

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An att…

Mitigation only
Fix from $1,950 2024-11-15